Most websites ask you to accept cookies. This one does not ask, because it has nothing to sell, to measure or to track. Two small items can be stored on your device — a language preference, and a note that you have seen our first-visit message — and neither is written unless you click for it. This page explains our position honestly, so that you can check it rather than take our word for it.
No analytics, no advertising, no tracking
When you visit ichina.ie, the act of loading a page writes nothing to your device. Our pages do not create a cookie, do not write to local storage or session storage, and do not open a browser database — not when they load, not when you move between them, and not when you open our settings panel.
We use no analytics service, no advertising network, no tag manager and no social media tracking. We do not embed video players, maps or fonts from other companies. On every page of this website, whenever the site is open, no other company receives any information about your visit. There is one exception, at one time only, and we describe it in full below: while the site is closed for maintenance, the sign-in that Chamber staff use to reopen it is protected by a security check supplied by Cloudflare, which loads only once you start using that sign-in form.
Because we run nothing that measures you or follows you, there is nothing here for you to accept or refuse, and no banner blocks your way. The only two things that can ever be stored on your device are listed under "What can be stored on your device" below, and each of them is written only when you click for it.
What can be stored on your device
There are exactly two, and this is the complete list of what this website stores on your device. Both belong to this website alone and can be read only by it. Neither holds a name, an account, or a number that identifies you, and neither can be joined up with anything you do on any other website. Neither is written unless you click for it.
- NEXT_LOCALE — language preference. A cookie. It holds one of two values, "en" or "zh", and nothing else. It is written only when you switch the language preference on — either on our first-visit notice or under Privacy and site settings — and it tells us which language to open when you arrive at an address that does not already name one. It is set by ichina.ie, not by anyone else; it expires six months after it is written; and while it exists your browser sends it to our server with every request, so our server can see it. Switching the preference off deletes it immediately.
- First-visit notice marker — local storage. Not a cookie: a short marker your browser keeps in local storage. It records that you closed the short message shown on a first visit, together with the date you closed it, so that the message does not come back. It contains no identifier of any kind, and it never leaves your device — it is not sent to our server. Our own code treats it as expired six months after that date.
You can remove both at any time, together, using "Clear everything stored on this device" under Privacy and site settings, or by clearing this site's data in your browser. If you clear them, the first-visit message may appear again the next time you open the site, because the record that you had seen it is one of the things you deleted.
Nothing else is stored on your device by this website. One other thing reads information from your device rather than storing anything on it — the security check described under "The security check on our maintenance page" further down, which exists only while the site is closed for maintenance. The next section explains what permits us to store the language cookie, and the law that governs it.
The language cookie
Our website is published in English and Simplified Chinese, and most addresses on it already name a language: /en/about is the English page, /zh/about is the Chinese one. Following a link inside the site keeps you in the language you are reading, and the cookie plays no part in that.
The cookie matters only when you arrive at an address that does not name a language — the plain ichina.ie, or a link someone sent you without the language in it. In that case our software looks for a cookie named NEXT_LOCALE. If it holds "en" or "zh", we open that language. If it is missing, or holds anything else, we use the language setting your browser sends with every request, and otherwise English.
Nothing writes that cookie except your own click on the language preference, whether on our first-visit notice or under Privacy and site settings. Switching it on writes it; switching it off deletes it. If you never switch it on, it is never there.
We do not treat this cookie as exempt from your permission. Regulation 5(3) of the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011) requires clear and comprehensive information and your consent before information is stored on your device. Regulation 5(5) lifts that requirement where the storage is strictly necessary for a service you have explicitly requested. The Article 29 Working Party, in Opinion 04/2012 on cookie consent exemption (WP 194, section 3.6), treats a language preference as falling within that exemption only for a browser session or a few hours, and says that keeping it for longer is instead permitted where the site gives clear information in a prominent place — in which case the user's own action is consent for the longer period. Ours lasts six months. So we do not rely on the exemption. We rely on your act of switching it on, made next to the description of exactly what it does, and you withdraw that permission by switching it off.
The Data Protection Commission's guidance on cookies and similar technologies makes the related point that the lifespan of any cookie must be proportionate to what it is for. Six months is our judgement of what makes a language preference useful without keeping it beyond its purpose. If you think that is too long, switch the preference off and the cookie is deleted.
A language code such as "en" or "zh" does not identify you, and it is not used for any other purpose.
One honest consequence of it being a cookie: while it exists, your browser sends it to our server with every request you make to this site. That is how it reaches us. Anything our server records about those requests is described in the next section, and is deleted after 30 days.
What our server records
This is the part most people are really asking about, so we set it out plainly.
Every website receives a request from your browser in order to send you a page, and that request necessarily contains technical information. Our web server writes that information to a log file. Each entry contains the IP address the request came from, the date and time, the address of the page or file requested, the response our server gave, and the browser identification string your browser sends.
We use these records only to keep the website running and secure: to find and fix faults, and to detect and block attacks and abuse. We do not use them to identify individual visitors, build profiles, measure audiences or produce visitor statistics.
These records are kept for 30 days and then deleted. They are not copied into our backups, so 30 days is the total time we hold them.
This is not a cookie, and it does not involve anything being stored on your device. It is described here for completeness, and in more detail in our Privacy Notice.
The staff area
Our staff use a separate, password-protected system to publish content on this website. That system sets a session cookie so that a signed-in member of staff stays signed in. It is strictly necessary for a service those staff members have explicitly asked for, so it needs no consent.
That system is not part of the public website. Visiting ichina.ie does not involve it and does not set that cookie.
The security check on our maintenance page
There is one time, and one page, at which this website loads something from another company. This section is the whole of it.
When we take the site down for scheduled maintenance, every address on it answers with a maintenance page instead of the page you asked for. That page explains what is happening, and it also carries the sign-in Chamber staff use to reopen the site. The sign-in is protected by a check called Turnstile, supplied by Cloudflare, which tells a person from an automated script.
Opening that page and reading it sends nothing to Cloudflare. The check is described on the page, but it is not fetched when the page loads: your browser fetches it the moment you start using the sign-in form — clicking or tapping into it, or moving to it with the keyboard. If you only read the page and leave, nothing on this website ever contacts Cloudflare. When the site is open, the check does not exist at all.
Two things happen when the check loads, and we would rather tell you than have you find them. Your browser fetches it from challenges.cloudflare.com, which sends Cloudflare your IP address, the browser identification string your browser sends with every request, and technical characteristics of your connection. And the check runs small scripts from Cloudflare inside your browser that examine how your browser behaves — that is how a check of this kind recognises a person without making you solve a puzzle. Reading information from your device in that way is governed by the same law as a cookie, whether or not a cookie is involved.
- Cloudflare Turnstile — the check on our maintenance page. Loaded from challenges.cloudflare.com, which is Cloudflare's address and not ours. It appears only while the site is closed for maintenance, only on the maintenance page, and only once you have started using the sign-in form on that page. Cloudflare's own documentation states that Turnstile does not use cookies to collect or store information of any kind; the one cookie Cloudflare documents alongside it belongs to a mode called pre-clearance, which this website does not use and could not use. What the check does do is read characteristics of your browser and send them, together with your IP address, to Cloudflare. None of that reaches us. When the sign-in is submitted, our server asks Cloudflare whether the check passed, and we deliberately leave your IP address out of that question.
Regulation 5(3) of S.I. No. 336 of 2011, set out under "The language cookie" above, requires your consent before information is stored on your device or read from it. Regulation 5(5) lifts that requirement where the storing or reading is strictly necessary to provide a service you have explicitly asked for. We rely on Regulation 5(5) here, and we can only do so because of how we have built it: the check does not load for someone who is merely trying to read the site, or who opens the maintenance page and reads it. It loads at the moment you start using the sign-in form, and what it protects is exactly the service you have just begun to ask for — the only way back into a closed site — against automated attempts that would use up the small number of tries the form allows and leave the people who need it unable to get in.
The Article 29 Working Party treated a measure of this kind — one that protects a sign-in form from abuse — as covered by that exemption (Opinion 04/2012 on cookie consent exemption, WP 194, section 3.3), and said in the same passage that the exemption does not extend to security a user has not asked for. That is the reason we do not run this check for everyone who happens to be shown the maintenance page. If we ever did, the exemption would not cover it, and we would ask your permission first.
Sending your IP address to Cloudflare is also a use of personal data under the GDPR, separately from the law on cookies. Our legal basis is our legitimate interests in the security and availability of our own systems (Article 6(1)(f)) — the same basis as our server records, described above. Cloudflare, Inc. is established in the United States and is certified under the EU–U.S. Data Privacy Framework, which the European Commission has decided provides an adequate level of protection for transfers of this kind. Cloudflare acts for us in running the check and states that it also uses what it sees to improve the check itself, and that the signals it collects are not used to identify, profile or target anyone.
If you would rather the check did not run, read the maintenance page and do not use the sign-in form. Reading it loads nothing from anyone, and every other page of this website loads nothing from anyone at any time.
If this ever changes
We may one day want to measure how the site is used, or to embed something from another service — a video, a map, or a registration tool for an event. None of that exists today. Nothing of the kind is installed, dormant, or waiting to be switched on. The one thing this website loads from another company is the security check described above: it is a security measure and not a measurement, it counts nothing, and it exists only while the site is closed for maintenance.
If we introduce anything that stores or reads information on your device beyond what is strictly necessary, we will ask for your permission first, and we will not do it until you agree. Specifically, we commit that:
- Nothing non-essential will run before you have made a choice.
- Refusing will be exactly as easy as accepting — one click, on the same screen, with buttons of equal prominence. There will be no pre-ticked boxes, and no design that pushes you towards agreeing.
- You will be able to change or withdraw your choice at any time, as easily as you gave it.
- We will tell you what each item does, who provides it and how long it lasts, before you decide.
The settings panel on this site is where any such choice would be made and unmade. It exists now, with one small thing in it, so that it does not have to be built in a hurry around a decision that has already been taken.
We will also update this page and change the review date before any such change goes live.
How to check for yourself
You do not have to trust this page. You can verify it. Open your browser's developer tools (usually the F12 key), go to the Storage or Application tab, and load any page on ichina.ie. If you have never switched the language preference on and never closed the first-visit message, you should see no cookies, no local storage and no session storage for this site at all. If you have done one or both, you should see exactly the one or two items listed above, holding exactly what we say they hold, and nothing else. The Network tab should show requests only to ichina.ie and its own subdomains. That holds for every page of this website, in both languages, whether the site is open or closed — including the maintenance page, for as long as you only read it. There is exactly one way to make another company's address appear there, and you can test it in both directions. While the site is closed, open the maintenance page with the Network tab already open and touch nothing: you should see no request to challenges.cloudflare.com at all, however long you leave it, and scrolling the page should not produce one either. Then click into the password field. One should appear, because that is the check described under "The security check on our maintenance page" above. It is the only request to another company this website ever makes, and it does not happen until you act. Anything else, on any page, at any time, contradicts this page.
If you find something that contradicts this page, please tell us at info@ichina.ie. We will investigate and correct either the page or the website.
Questions
If you have a question about this page, email info@ichina.ie. Our Privacy Notice explains how we handle personal data generally, and how to contact the Data Protection Commission if you wish to complain.
This page was last reviewed on 26 July 2026.
